VDB
BDU%3A2025-14415
BDU%3A2025-14415
PUBLISHED
CVSS 9.399999618530273 CRITICAL
Уязвимость модуля eventlet.wsgi библиотеки Eventlet, позволяющая нарушителю обойти существующие ограничения безопасности
Risk Scores
CVSS 2.0
9.399999618530273
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Canonical Ltd., Сообщество свободного программного обеспечения, ООО «Ред Софт», Red Hat Inc., АО «ИВК» | Ubuntu, Debian GNU/Linux, РЕД ОС (запись в едином реестре российских программ №3751), Red Hat OpenShift Container Platform, Red Hat OpenStack Platform, АЛЬТ СП 10, Eventlet |
Timeline
- Nov 18, 2025 CVE Published
- Dec 3, 2025 CVE Updated
References
- https://lists.debian.org/debian-lts-announce/2025/09/msg00003.html url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ url
- https://github.com/eventlet/eventlet/commit/0bfebd1117d392559e25b4bfbfcc941754de88fb url
- https://github.com/eventlet/eventlet/pull/1062 url
- https://github.com/eventlet/eventlet/security/advisories/GHSA-hw6f-rjfj-j7j7 url
- https://ubuntu.com/security/CVE-2025-58068 url
- https://access.redhat.com/security/cve/cve-2025-58068 advisory
- https://security-tracker.debian.org/tracker/CVE-2025-58068 advisory
- https://altsp.su/obnovleniya-bezopasnosti/ advisory